The Threema secure messaging service was subjected to multiple distributed denial-of-service (DDoS) attacks earlier this week, leading to significant service interruptions. Users reported issues starting Tuesday evening UTC, with some experiencing delayed messages and connectivity problems. The company initially attributed the problem to a network outage at its colocation partner, but later confirmed it was under a series of DDoS attacks.
Threema stated that the attacks were particularly challenging to defend against due to their large scale and the attacker's continuous modification of tactics. The threat actor frequently changed attack patterns, making it difficult for mitigation measures to adapt effectively. The attacks targeted both Threema's infrastructure and that of its colocation partner, Nine.
The attacks rendered Threema's service temporarily unavailable or only partially available on Tuesday evening and Wednesday morning. While Threema typically mitigates DDoS attacks without noticeable impact, the persistence and evolving nature of these attacks caused intermittent outages for users in various regions, including Switzerland, India, and China. Threema On-Prem users, who operate on their own infrastructure, were not affected by these disruptions.
Threema, a Swiss-developed paid messaging application known for its focus on security and privacy, relies on its own server infrastructure in Switzerland. The company issued a post-mortem report detailing the nature of the attacks and the difficulties encountered in mitigating them. It remains unclear whether Threema was the primary target or if the attacks were part of a broader campaign against multiple entities.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
The Threema secure messaging service experienced severe disruptions due to multiple large-scale distributed denial-of-service (DDoS) attacks. The attacks were difficult to mitigate because the threat actor constantly changed patterns and targeted both Threema and its colocation partner. This incident highlights the persistent challenge of defending against sophisticated DDoS campaigns, even for services focused on security.